The success of an organization's information and cyber security program to protect its sensitive data depends on several key integrated components. You can't only assign this responsibility to your IT staff or assume that because your data is stored in the cloud there is nothing left to do.
One of the most important factors that is often overlooked is the role that managers within an organization play to ensure success through their own behaviour and attention to this issue. As fundamental as it sounds, it cannot be said enough that managers must look inward to ensure they are playing their part in building a corporate culture and accountability-based behaviour that consistently prioritizes information security.
Leaders serious about this topic instil a corporate culture that values information security by setting a positive example in how you, and the staff in your office, conduct your daily activities. Managers who believe they are too busy to follow security policies and procedures operate under a double standard different than how the rest of the organization is expected to act are in trouble. Managers must set the bar for their own activities higher than the standard, recognize when improvements need to be made, and should strive to exceed the expectations they place on staff.
Managers at all levels need to communicate with their staff about information security. It is critical to continually reinforce that this subject is important to the organization, relies on the actions of everyone, and must be a daily priority within the organization.
If your organization is going to communicate that information security is a priority, managers must be ready to support this by allocating sufficient resources to the issue, dedicating time to implement security policies and processes, and committing to monitoring compliance.
Our security experts at Castellan have seen examples set by managers that significantly improved the corporate culture or an organization to take information security seriously. These managers committed to this priority in their daily actions and routinely made the tough decisions required to secure their information.
Not only is it a manager's responsibility to ensure their information security program is run successfully, but it is also just as critical that leaders pay attention to how they support the program, what they do daily with their own behaviour, and how they communicate with staff. Managers need to 'own' this corporate responsibility and ensure that the proper culture, one that values and prioritizes information security, is engrained into their organization.
Castellan Information Security is a Winnipeg-based 'end-to-end' information security company that specializes in information security and have worked with both large and smaller private and public organizations to help them reach their information security objectives. If you have questions about this article or would like to speak to us about how our services can help your company protect its information please feel free to contact us directly at info@castellaninformationsecurity.com.